CVE-2025-48583: High severity Google Android vulnerability
Published Dec 1, 2025
·Updated
In multiple functions of BaseBundle.java, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
4 affected components
Google Android
Google Android=14.0
Google Android=15.0
Google Android=16.0
Remediation
Event History
Dec 1, 2025
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
Affected Software
Dec 8, 2025
CVE Published
via MITRE·04:57 PM
Data Sourced
via MITRE·04:57 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48583?
CVE-2025-48583 has a high severity rating due to its potential for arbitrary code execution and local privilege escalation.
2
How do I fix CVE-2025-48583?
To fix CVE-2025-48583, update your Android device to the latest version provided by Google.
3
What versions of Android are affected by CVE-2025-48583?
CVE-2025-48583 affects Android versions 14.0, 15.0, and 16.0.
4
Is user interaction required for exploiting CVE-2025-48583?
No, user interaction is not needed for exploiting CVE-2025-48583.
5
What could be the impact of CVE-2025-48583 if exploited?
If exploited, CVE-2025-48583 could lead to local escalation of privilege, allowing an attacker to execute arbitrary code.